Why pre-screen control system security experts before the technical panel
Standard security practice does not transfer here. An active scan can crash a controller, a patch requires a production outage nobody will authorise, and taking a device offline during an incident can be more dangerous than the intrusion. Experts worth hiring know exactly what they will not do on a live plant. A short screen asks what they would never scan.
What actually matters when screening Cyber-Physical Systems Security Expert candidates
- 01
Technical depth
Probe depth in OT protocols (Modbus TCP, DNP3, EtherNet/IP, PROFINET), PLC and safety instrumented system architecture, and how they apply IEC 62443 zones and conduits to a live plant.
- 02
Real incidents and findings
Ask for specific engagements: firmware teardowns, HMI or historian compromise, Purdue Level 3 network captures, or response to an incident that risked physical process disruption.
- 03
Risk judgement
Test how they weigh availability and safety against patching, when compensating controls beat a shutdown window, and how they treat legacy Windows HMIs that cannot be upgraded.
- 04
Getting things fixed
Look for evidence they moved plant engineers and vendors to act: change windows negotiated, ICS asset inventory built, secure remote access replacing vendor modems.
Pre-screening questions to ask Cyber-Physical Systems Security Expert candidates
12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.
Secured live systems
3 questions01Can you describe your experience securing systems that control physical processes?
Listen forWork on live operational systems, with the constraints of production described from experience.
Experience confined to corporate networks, or plant systems treated as ordinary infrastructure.
02Can you discuss a time you reduced a significant security risk in one of these systems?
Listen forA specific risk with a control implemented without disrupting operations, and evidence it worked.
Risks documented without mitigation, or controls proposed that operations refused to accept.
03What experience do you have with industrial control systems and their security?
Listen forControl protocols and their lack of built-in authentication understood from real environments.
Control protocols unfamiliar, or their inherent insecurity not recognised as the starting point.
Assessment suits plant
3 questions04What methods do you use to assess vulnerabilities in these systems?
Listen forPassive monitoring and configuration review preferred, with active testing only in agreed windows.
Standard scanning applied to production, or assessment methods that risk stopping a process.
05What is your approach to penetration testing in these environments?
Listen forTesting on a representative offline environment, with live testing scoped very carefully if at all.
Testing performed on production, or the risk of disrupting a physical process not acknowledged.
06What is your approach to threat modelling for these systems?
Listen forConsequences modelled in physical terms, with safety impact treated as the primary concern.
Threat modelling focused on data loss, or physical consequences not part of the analysis.
Legacy handled
4 questions07How do you approach securing legacy equipment in these environments?
Listen forCompensating controls applied around devices that cannot be patched or replaced for years.
Replacement proposed as the answer, or unpatchable devices left directly reachable.
08How do you ensure the security of embedded devices in these systems?
Listen forFirmware integrity, default credentials and physical access all addressed for field devices.
Default credentials left in place, or firmware provenance never verified.
09What is your experience with real-time operating systems and their constraints?
Listen forTiming constraints understood, with security controls chosen so they do not disturb determinism.
Security agents proposed for real-time devices, or timing impact not considered.
10What approaches do you use to secure communication within these systems?
Listen forSegmentation and authentication added where protocols lack it, without breaking existing traffic.
Encryption proposed where latency forbids it, or existing traffic flows never analysed first.
Safe incident response
2 questions11How do you handle incident response in these environments?
Listen forSafety and process continuity considered before containment, with operations involved in decisions.
Devices isolated unilaterally, or containment decisions made without operations present.
12How do you balance security controls against system performance and usability?
Listen forControls chosen to fit operational reality, with operator workflow considered so they are not bypassed.
Controls that operators work around, or usability treated as unimportant next to security.
How to score responses
Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.
Technical depth
35%5Names controller families and protocol quirks precisely, and maps 62443 security levels to real segmentation decisions rather than reciting the standard.
Real incidents and findings
30%5Recounts named assessments with findings, exploited paths, and the physical consequence prevented, including evidence gathered without disrupting production.
Risk judgement
20%5Ties risk ratings to process hazard consequence, argues for compensating controls where downtime is unaffordable, and states what they would accept.
Getting things fixed
15%5Shows remediation completed with control engineers as allies, citing before and after states such as removed dual-homed hosts or jump host adoption.
A scan can crash a controller and a patch needs an outage nobody will authorise. A one-way video screen asks about that.
Try it on HirevireScreening FAQ
Process basics
How long should a pre-screening round for this role take?
Fifteen minutes across eight to ten questions, answered async. Enough to establish systems they secured, test their assessment approach, and check legacy and incident handling.
Does enterprise security experience transfer to this role?
Partly. The threat concepts transfer; the operational constraints do not. Someone who has only worked in corporate IT environments will propose controls that stop production within a week.
Evaluating answers
What is the strongest signal when screening this role?
What they would never scan on a live system. Experts with plant experience name fragile controllers and describe passive methods. Anyone who would scan everything will cause an outage.
How do I judge their legacy handling?
Ask how they secure a device that cannot be patched for a decade. Real answers cover segmentation, monitoring and compensating controls. Anyone whose answer is upgrade has not met the equipment.
























